Skip to content

Hide Navigation Hide TOC

Shell Injection Data Exfiltration — Piped Command Exfiltration via Bash - ATR-2026-00863 (79db7487-9bd9-50b5-9b5b-12fc44db5e98)

Detects shell command injection payloads that combine a seemingly legitimate shell operation with a piped or chained data exfiltration command. The attack embeds a benign-sounding task (ping, git status, grep for audit) with a follow-on command that reads sensitive files (.env, credentials, passwords) and POSTs or transmits the data to an attacker-controlled endpoint via curl, wget, nc, or Python urllib. Derived from the exfil-shell-injection corpus. This extends rule ATR-2026-00201 (credential pipe exfiltration) to cover shell script compound command patterns beyond environment variable pipes.

Cluster A Galaxy A Cluster B Galaxy B Level
LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern Shell Injection Data Exfiltration — Piped Command Exfiltration via Bash - ATR-2026-00863 (79db7487-9bd9-50b5-9b5b-12fc44db5e98) Agent Threat Rules 1
Shell Injection Data Exfiltration — Piped Command Exfiltration via Bash - ATR-2026-00863 (79db7487-9bd9-50b5-9b5b-12fc44db5e98) Agent Threat Rules Exfiltration Over C2 Channel - T1041 (92d7da27-2d91-488e-a00c-059dc162766d) Attack Pattern 1
Credentials In Files - T1552.001 (837f9164-50af-4ac0-8219-379d8a74cefc) Attack Pattern Shell Injection Data Exfiltration — Piped Command Exfiltration via Bash - ATR-2026-00863 (79db7487-9bd9-50b5-9b5b-12fc44db5e98) Agent Threat Rules 1
Unix Shell - T1059.004 (a9d4b653-6915-42af-98b2-5758c4ceee56) Attack Pattern Shell Injection Data Exfiltration — Piped Command Exfiltration via Bash - ATR-2026-00863 (79db7487-9bd9-50b5-9b5b-12fc44db5e98) Agent Threat Rules 1
LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern Shell Injection Data Exfiltration — Piped Command Exfiltration via Bash - ATR-2026-00863 (79db7487-9bd9-50b5-9b5b-12fc44db5e98) Agent Threat Rules 1
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) Attack Pattern Credentials In Files - T1552.001 (837f9164-50af-4ac0-8219-379d8a74cefc) Attack Pattern 2
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) Attack Pattern Unix Shell - T1059.004 (a9d4b653-6915-42af-98b2-5758c4ceee56) Attack Pattern 2